{"id":"AZL-104901","summary":"CVE-2026-6103 affecting package php 8.3.33-1","details":"phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips the wrong number of data blocks and interprets attacker-controlled file content as the next TAR header, which lets a crafted archive inject entries that PharData reports and extracts as if they were genuine.","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T21:17:23Z","upstream":["CVE-2026-6103"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6103"}],"affected":[{"package":{"name":"php","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/php"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"8.3.33-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104901.json"}}],"schema_version":"1.9.0"}